CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2024-12008Public Exploit

W3 Total Cache - Information Disclosure (CVE-2024-12008)

PublishedJan 14, 2025
First SeenJun 25, 2026
Last Seen
Reported
CVSS5.3
wordpresscms

Description

The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks. Note: the debug feature must be enabled for this to be a concern, and it is disabled by default.

psychologyCrowdSec Analysis

CVE-2024-12008 is an information disclosure vulnerability in the W3 Total Cache plugin for WordPress, affecting all versions up to 2.8.1. When the debug feature is enabled, unauthenticated attackers can access a publicly exposed debug log file, potentially revealing sensitive information such as nonce values. This exposure could facilitate further attacks, including cross-site request forgery (CSRF), if exploited.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network observations suggest that most exploitation of CVE-2024-12008 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2024-12008. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit this vulnerability by directly accessing log files such as /wp-content/cache/log/000000/pagecache.log and /wp-content/cache/log/000000/minify.log, exposing sensitive information from W3 Total Cache plugin debug logs. These endpoints are targeted to retrieve data that may aid in further attacks, such as nonce values or credentials.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2025-01-14
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.